Phpclanwebsite uploader.php Path Disclosure

Description

Vulnerability Description

Phpclanwebsite contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker who is logged in as a clan administrator assigns a backslash to an the "page" variable, which will disclose the software's installation path in an error message, resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.

Solution Description

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: add the following code to the end of the config.php file:

ini_set('display_errors', false)

Short Description

Phpclanwebsite contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker who is logged in as a clan administrator assigns a backslash to an the "page" variable, which will disclose the software's installation path in an error message, resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.

All product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement.If you are an owner of some content and want it to be removed, please mail to content@vulners.com Vulners, 2017